CarGurus Data Breachcheck your eligibility

In February 2026, online automotive marketplace CarGurus was reportedly targeted by the cybercrime group known as ShinyHunters. Reportedly, the attackers claim to have gained access to 12.5 million customer accounts, which is key to their typical “pay or leak” extortion strategy.
We’ve partnered with KP Law, a specialist law firm for data breach claims. KP Law is exploring a potential group action claim against CarGurus. You can check eligibility for a potential data breach claim. If eligible, you can sign up to claim with KP Law. If enough claimants come together, KP Law will let you know and fight to secure compensation on a NO-WIN, NO-FEE* basis.
In this matter, if it is successful, you will pay 25% of the amount that is recovered plus the cost of any After the Event Insurance. Termination fees may apply if you fail to co-operate with your lawyer or withdraw from the claim.
The first step in getting compensation
Sign up for a potential CarGurus data breach claim to register your interest to be notified if the claim moves forward.
THE FACTS SO FAR
What do we know about the CarGurus data breach?
In February 2026, online automotive marketplace CarGurus was reportedly targeted by the cybercrime group ShinyHunters, who claim to have accessed internal systems using sophisticated voice phishing ('vishing') techniques.
The attackers claim to have compromised up to 1.7 million private company records, including sensitive customer information and internal data.
According to reports, a 6.1GB archive was discovered on the dark web. This archive is thought to have contained a leaked database with up to 12.5 million email addresses associated with CarGurus customers, along with personal identifiers such as device information and car finance pre-qualification data.
Eligible individuals whose data was exposed in the data breach can sign up for the potential claim and register their interest in a potential group action claim for compensation.
FREQUENTLYASKED QUESTIONS
After the ShinyHunters group gained access to CarGurus systems, they accessed 1.7 million private company records and threatened to release the data publicly unless a ransom was paid.
Sometime later, a 6.1GB archive was leaked on the dark web, containing up to 12.5 million email addresses of CarGurus customers.

